Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bearsyankees
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
bearsyankees
10d ago
+1 -- kudos to the Baseten team for their super professional response to all of this, it is clear why they are a generational company (-- Alex from Strix)
2.
▲
by
bearsyankees
11d ago
yes! app.strix.ai/demo
3.
▲
by
bearsyankees
11d ago
Hate to burst your bubble but wasn't Claude......
4.
▲
by
bearsyankees
11d ago
You can also just do an external pentest -- Github is for continuous CI/CD coverage
5.
▲
by
bearsyankees
11d ago
Yeah understood — we need to make sure you own the domain first though
6.
▲
by
bearsyankees
11d ago
Neither, actually :)
7.
▲
by
bearsyankees
11d ago
We've made a lot of awesome changes recently, would love any feedback on the latest version :)
8.
▲
by
bearsyankees
11d ago
Yeah honestly I wasn't too familiar with this beforehand but now have a sense of the best practices going forward
9.
▲
by
bearsyankees
11d ago
Let us know if you have any feedback!
10.
▲
by
bearsyankees
11d ago
Yeah... interesting paradigm
11.
▲
We got admin access to Baseten's production GitHub in 25 minutes
(strix.ai)
244 points
by
bearsyankees
11d ago
|
133 comments
12.
▲
by
bearsyankees
11d ago
We were (and still are) considering them as an inference provider and did a quick check first... but kudos to their team for the fast patch
13.
▲
We wanted to use Baseten for inference, we got admin access to their GitHub
(strix.ai)
9 points
by
bearsyankees
16d ago
|
0 comments
14.
▲
by
bearsyankees
1mo ago
If this is the case then IMO all the more reason to publicize it -- my SSN shouldn't be exposed just because I applied for a lease [ and we shouldn't just brush that off as something that is a given ]
15.
▲
by
bearsyankees
1mo ago
Also, as far as I know, no residents were ever alerted that their data was exposed so this also is a bit of a public disclosure angle
16.
▲
by
bearsyankees
1mo ago
Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn't a c
17.
▲
by
bearsyankees
1mo ago
Thanks!! Just trying to protect other's (and in this case, my own) data :)
18.
▲
by
bearsyankees
1mo ago
yep
19.
▲
A Blackstone real estate company exposed SSN digits, DOBs, addresses and more
(alexschapiro.com)
123 points
by
bearsyankees
1mo ago
|
56 comments
20.
▲
by
bearsyankees
2mo ago
yeah you mean because OAI is only whitebox? or expand on that a bit, haven't played around a ton w the oss codex sec
21.
▲
by
bearsyankees
2mo ago
would love it to see it h2h against https://github.com/usestrix/strix (45k stars)
22.
▲
by
bearsyankees
2mo ago
granola's disclosure: https://docs.granola.ai/help-center/policies/security-contri...
23.
▲
Finding a 1 click account takeover (and webcam access) in Granola
(strix.ai)
6 points
by
bearsyankees
2mo ago
|
1 comments
24.
▲
by
bearsyankees
2mo ago
https://www.strix.ai/blog/granola -> technical writeup
25.
▲
Granola Discloses a 1 Click Session Takeover of Its Notes App
(docs.granola.ai)
3 points
by
bearsyankees
2mo ago
|
1 comments
26.
▲
One Click Account Takeover in Granola AI Notetaker
(strix.ai)
7 points
by
bearsyankees
2mo ago
|
0 comments
27.
▲
CVE-2026-59208: Cross-Issuer Account Takeover in n8n
(strix.ai)
20 points
by
bearsyankees
2mo ago
|
10 comments
28.
▲
by
bearsyankees
5mo ago
oh apologies, thanks for the reminder
29.
▲
by
bearsyankees
5mo ago
appreciate the feedback!!
30.
▲
by
bearsyankees
5mo ago
https://x.com/strix_ai/status/2051361018450948511
More ›